I am an employee under the employment contract, temporary contract, consultant service contract or any other service contract (“Contract”) as the case may be who is the data subject, consent this form to Puumsoft Company Limited collectively called “Company”) where is the data controller.
I hereby consent the Company to store, use and disclose my sensitive data e.g. race, religious, health data (including health history, drug allergy, food allergy, any allergy, sick leave data, illness, accident), criminal record, disability, biometric including any sensitive data which may effect to me as same as such data type (collectively referred to as “Sensitive Data Processing”) for the following purposes;
Processing Area :
|
Job Application and Employment Management
|
Activities :
|
(1) Recruitment activities by Puumsoft including when Candidate and Employee contacts Puumsoft directly and internal recruitment.
|
(2) Examining criminal record (only specific position)
|
|
Processing Area :
|
Work performance management
|
Activities :
|
(1) Applying or renewing visa and work permit and requesting any permission for working
|
(2) Requesting for food allergy and any other allergies record in order to train or arrange for related activities.
|
|
Processing Area :
|
Compensation and welfare management
|
Activities :
|
(1) Recording medicine history and alleviating accident, incident, emergency case or danger against life, body, health of employee, including the security of employee
|
(2) Managing life insurance, group insurance, underwriting, reinsurance, consideration for insurance claim
|
(3) Disclosing employee data to outsource and consultant e.g. disclosure for survey and compensation analysis
|
(4) Managing advertising, public relations of which employee is a presenter either wholly or partly express himself in the media of Company.
|
(5) Birthday announcement and condolences on loss of employee’s family member and the request of food allergy record in order for activity and party arrangement
|
I acknowledged that Company may process Sensitive Data by itself or by the third parties, such as;
(1) Insurer and group insurer and reinsurer
(2) Service providers who related to human resources management e.g. bank, asset management company, human resources system administrator, training service provider, data storage in paper and electronic form etc.
(3) Service provider as related to building, place, hotel, travelling, and any activities
(4) Consultation services
(5) Hospitals or medical centers
(6) Government and regulators e.g. Office of Insurance Commission, Anti-Money Laundering Office, Royal Thai Police, Social Security Office, Revenue Department, police, prosecutor, court or any relative government authorities.
Period of Personal Data processing
I hereby consent the Company to store, use and disclose my sensitive data for the above purposes within the period of 10 years from the termination date of the Contract.
Personal Data Owner’s Rights
(1) Request a copy or a certified copy of your Sensitive Data;
(2) Request to make a change or correct your Sensitive Data;
(3) Request to suspend the use or the disclosure of your Sensitive Data;
(4) Request to erase or destroy your Sensitive Data;
(5) Request to disclose the method of obtaining your Sensitive Data for the case which your consent has not been made;
(6) Request to cancel your consent which you have previously made;
(7) Request to transfer your Sensitive Data to other data controller;
(8) Contact us or any relevant authorities, if necessary;
(9) Compliant us or Data Processor or our employee or our service provider in case such person did not comply with Applicable Personal Data Protection Law.
Remark:
Please note that if you choose to exercise your right in (3) (4) and (6), we will not be able to provide welfares as related to your withdrawal consent to you or oblige under Contract which effects to the termination.
Please contact HR in case you would like to exercise your right above.
1. What is Personal Data?
Personal Data is any other data which identify yourself (no matter it can be identified by itself, or together with other information) comprises of 2 groups as follows;
Group 1: Basic information e.g. name, surname, age, address, gender, occupation, married status, nationality, id card number, passport and visa information, bank account, driver license, telephone number, e-mail, Line id, Facebook, cookies website, picture, emergency contact, car license etc
Group 2: Work information e.g. application details, education, work experience, contract, work license, social security, compensation fund, provident fund, employee number, salary, compensation, bonus, position, welfare, tax, work assignment details, career goal, performance appraisal, training record, leave and absence record, illegal and/or work discipline behavior, reason of termination, security data, communication data and record of using computer, telephone, internet and e-mail etc.
Sensitive Data is Personal Data relating to racial or ethnic origin, religious or philosophical beliefs, data concerning a natural person’s sex life, criminal record, data concerning health, disabilities, biometric data etc.
Candidate is the applicant for permanent employee or temporary employee or freelance person or employee who is under outsourcing person. Applicant may proceed by his/herself or internal recruitment or referral program or head hunter.
Employee is the Candidate who is selected and enter into the employment contract with us and is permanent employee or temporary employee or outsourcing person or freelance person who works at Viriyah’s office.
2. Personal or Sensitive Data Processing
2.1 2.1 You acknowledges that under the purposes of job application, employment contract, employment term contract, consulting contract and other service contracts (“Contract”), we is entitled to collect, use and disclose your Personal Data and Sensitive data (“Processing”)
We needs to correctly, completely, sufficiently receive your personal information in order to perform the obligations under job application, Contract, regulations, internal rules and/or our operating rule and/or performance under applicable law. Should we did not correctly, completely and sufficiently receive your personal information, it may result in the delay or any inconvenience of our performance under Contract or rule binding between Viriyah and Candidate or Employee. In case of necessity, we may reject any obligations to Candidate or Employees in order to comply with the terms in the Contract and applicable laws. However, we respects your personal right and will process Personal data and Sensitive data based on legitimate purposes.
Below are details of our processing activities:
Processing Area
|
Activities
|
Basis for Processing
|
Job Application and Employment Management [self-managing and outsource performing]
|
Recruitment activities by Viriyah including when Candidate and Employee contacts Viriyah directly and internal recruitment.
|
Contract
|
Employee applied the job from referral program or from recruitment outsourcing service provider.
|
Consent
|
Examining bankruptcy name list and risk assessing according to Anti-Money laundering and Counter-Terrorism laws (“AMLO”) (only specific position)
|
Contract/lawful basis
|
Examining criminal record (only specific position)
|
Consent
|
Interviewing, examining education background or working experience history from other sources, data analysis, comparison, employee selection and contract process.
|
Contract/ legitimate interest
|
Work performance management [self-managing and outsource performing]
|
Employee record, employee card, equipment, tool, computer, mobile phone, e-mail, username & password for accessing necessary system and other related matters in order to prepare working, training or test.
|
Contract
|
Applying or renewing visa and work permit and requesting approval relating to work performance
|
Contract/ lawful basis/consent (relating to sensitive data)
|
Requesting for food allergy and any other allergies record in order to train or arrange for related activities.
|
Consent
|
License revocation (only sale position or any position as required by law) and personal data update for government system
|
Contract/ lawful basis
|
Compensation and welfare management [self-managing and outsource performing]
|
Managing salary, remuneration, wage, bonus, overtime wage, accommodation cost, travel fee and any other benefits for employee
|
Contract/lawful basis
|
Managing social security fund, provident fund and workmen compensation fund
|
Contract/lawful basis
|
Managing employment taxes e.g. withholding tax
|
Contract /lawful basis
|
Managing welfare, protection, accidental and dangerous alleviating measure, report and medical care service
|
Contract/lawful basis/legitimate interest
|
Recording medicine history and alleviating accident, incident, emergency case or danger against life, body, health of employee, including the security of employee
|
Consent/protecting or preventing danger against life, body or health of person
|
Managing life insurance, group insurance, underwriting, reinsurance, consideration for insurance claim
|
Contract/legitimate interest/consent (as related to sensitive data)
|
Disclosing employee data to outsource and consultant e.g. disclosure for survey and compensation analysis
|
Consent
|
Birthday announcement and condolences on loss of employee’s family member and the request of food allergy record in order for activity and party arrangement
|
Consent
|
Managing employee’s activities e.g. birthday party, new year party, any party and outing trip for employee.
|
Contract/legitimate interest
|
Managing day off, leaves and late arrival
|
Contract/lawful basis
|
Managing advertising, public relations of which employee is a presenter either wholly or partly express himself in the media of Viriyah.
|
Consent
|
Announcement as a new comer, candidates or employee of the month/year, long service award, promotion and relocation of employee.
|
Legitimate interest
|
Seizing of salary or remuneration as required by the order of execution department or official receiver in bankrupt case.
|
Lawful basis
|
Training and performance evaluation management [self-managing and outsource performing]
|
Training and exam testing for any area of knowledge of employee.
|
Contract/legitimate interest
|
Goal setting, performance evaluation, promotion, salary and bonus review.
|
Contract/legitimate interest
|
Compliant, Dispute, Lawsuit and Risk Assessment Management [self-managing and outsource performing]
|
Monitoring, investigating fraud or illegal behavior in accordance with law, rule and working regulations, including disciplinary action consideration.
|
Contract/lawful basis/legitimate interest
|
Taking any action for monitoring, investigation, suing or undertaking any measures to protect lawful or contractual right.
|
Contract/lawful/legitimate
|
Reporting fraud case of employee to regulator and any authorized officer as required by law e.g. police, OIC, AMLO, revenue department, execution office, Royal Thai Police.
|
Lawful/legitimate interest
|
Termination Management [self-managing and outsource performing]
|
Managing resignation, retirement, termination, informing thereof to related government e.g. Revenue Department, Bank, Social Security Office, Immigration Office
|
Contract/lawful basis
|
2.2 We will strictly and properly implement the Personal Data security measure and be compliant with Privacy Policy in order to protect your Personal Data or Sensitive Data from any loss, destroying, modifying, accessing or disclosing without permission or legality in accordance with Data Security Policy and Procedure and IT Security Guideline and Policy.
2.3 If there is any change and/or adding of the purpose of processing e.g. processing based on contract or lawful basis etc., we will inform you of new purpose via Viriyah website, poster announcement or e-mail. We will record such changes for evidence. In addition, we may request your consent before processing any activities of new purposes (if consent required by law).
3. We process your Personal Data restrictively
3.1 We will restrictively process your Personal Data or Sensitive Data by using legitimate and fair method and within the scope of the specified objective.
3.2 Other than the specified objective, we will obtain your consent prior to processing Personal Data; unless
(1) It is required by laws;
(2) It is beneficial to you, given that it is impossible to obtain your consent at that time;
(3) It is beneficial to your or someone else’s life, health or security;
(4) It is for a purpose of investigation of an officer or judicial process of court;
(5) It is beneficial to research or statistics preparation.
3.3 In case of necessity, we may collect your Sensitive Data for a purpose of Contract, performing regarding Contract and other agreement as related to employment. We however will not collect your Sensitive Data which is adverse to your reputation or discriminating; unless
(1) You give a consent to us;
(2) It is required by laws;
(3) It is beneficial to you, given that it is impossible to obtain your consent at that time;
(4) It is beneficial to your or someone else’s life, health or security;
(5) It is for a purpose of investigation of an officer or judicial process of court;
(6) It is beneficial to research or statistics preparation.
3.4 We may store your Personal Data together with your Personal Data that we have received from other sources and may request your consent (in case consent required by law) for abovementioned purpose, for updating Personal Data, or improving our services.
4. We may disclose your Personal Data to Data Processor or any authorities as required by laws
4.1 In order to perform the obligation of job application, Contract and/or other agreement as related to abovementioned objective, we may transfer or disclose your Personal Data and/or Sensitive Data to data processor, third party who is the advisor or service provider located both inside and outside country.
4.2 We store your Personal Data and/or Sensitive Data through Viriyah Group's Server (On Premise).
4.3 We may disclose your Personal Data and/or Sensitive Data to Viriyah, our affiliate, internal and external audit, The Office of Insurance Commission, Anti-Money Laundering Commission, Anti-Money Laundering and Counter-Terrorism Office located both inside or outside country, police officer, public prosecutor, court, legal execution enforcement officer, legal official receiver, Revenue Department officer, or any other office as required by relevant laws.
5. Your participation as Personal Data owner
5.1 If you would like to know how we process your Personal Data or Sensitive Data, you can send an email to HR When we receive your email, we will feedback you the existence or the detail of your Personal Data within appropriate time.
5.2 If you think that your Personal Data or Sensitive Data is not accurate, you can request us to make change or amend your Personal Data or Sensitive Data. In this regard, we may reject your request and we will record the rejection or objection of such request with reason as an evidence.
5.3 You have the right to check the existence, the type of your Personal Data and/or Sensitive Data, the using objective of your Personal Data and Sensitive Data. In addition, you also have the right to:
(1) Request a copy or a certified copy of your Personal Data and/or Sensitive Data;
(2) Request to make a change or correct your Personal Data and/or Sensitive Data;
(3) Request to suspend the use or the disclosure of your Personal Data and/or Sensitive Data;
(4) Request to erase or destroy your Personal Data and/or Sensitive Data;
(5) Request to disclose the method of obtaining your Personal Data and/or Sensitive Data for the case which your consent has not been made;
(6) Request to cancel your consent which you have previously made;
(7) Request to transfer your Personal Data and/or Sensitive Data to other data controller;
(8) Contact us or any relevant authorities, if necessary;
(9) Compliant us or Data Processor or our/its employee or our/its service provider in case such person did not comply with Applicable Personal Data Protection Law.
Remark:
If we process your Personal Data and/or Sensitive Data based on Contract, legitimate interest or legal obligation basis, we reserve our right to refuse your right in (3) and (4).
Please note that if you choose to exercise your right in (3) (4) and (6), we will not be able to perform the obligations under Contract which might result in Contract termination and/or the inability to provide the welfare to you.
6. Period of Personal Data processing
We reserve our right to process and disclose your Personal Data and your Sensitive Data and any relevant authorities as required by laws, whichever the case may be, within 2 years from the job application date (for Candidate) and 10 years from the expiration date of Contract (for Employee).
7. Changes to this Privacy Policy
7.1 We review this Privacy Notice regularly and reserve the right to make changes at any time to take account of changes in our services, operation and your suggestion. We will either notify or send a notice to you regarding the change of this Privacy Policy before making any change. You can access this Privacy Notice to People Net, poster announcement or e-mail.
7.2 If you have any question, please contact us at:
Viriyah Insurance (Public) Company Limited
121/28, 121/65 RS Tower, Ratchadapisek Rd., Dindaeng, Dindaeng, Bangkok 10400 (+66)2-129-8888
Visit our website at: https://www.viriyah.co.th/
Tel. (+66)2-129-8888
Contact Data Protection Officer:
• General case related to exercise of your Personal Data right at HR
• Compliant case related to Personal Data and/or Sensitive Data at e-mail DPO
This policy is effective from 14 December 2020.